Dwipanjit HandiqueSEBI Registered Research Analyst · INH000028936
← Back to home

Privacy Policy

What personal data is collected, why it is held, who it is shared with, and how long it is kept.

Last updated 12 August 2026 · Applies to dwipanjithandique.in and the client dashboard

This policy explains how Dwipanjit Handique, a Research Analyst registered with the Securities and Exchange Board of India under registration number INH000028936 ("I", "me"), handles personal data. It covers this website, the client dashboard, and the onboarding process used to take on a research client.

The short version. I collect the information needed to verify who you are, to enter into a research agreement with you, to take payment, and to deliver research. I do not sell personal data, I do not share it for advertising, and I do not use it to profile you for anything other than the service you asked for. Some of it I am legally required to keep for at least five years even after you leave.

1. Who is responsible for your data

Dwipanjit Handique, SEBI Registered Research Analyst, registration number INH000028936, is the data fiduciary for the personal data described here. Contact details are at the end of this page. There is no separate company: this is an individual registration, and I am personally accountable for the data.

2. What is collected, and why

DataWhy it is collectedWhere it comes from
Name, email address, mobile number To identify you, to contact you about your subscription, and to send the agreement and receipts You, or your Google account if you sign in with Google
PAN and date of birth Mandatory for KYC. SEBI requires a Research Analyst to verify a client's identity through a KYC Registration Agency before taking them on You
KYC record: address, identity and address proof references, and related fields held by the KRA To confirm your KYC is valid and to keep the client record SEBI requires Retrieved from the KRA, not typed in by me
Risk profile and suitability answers To assess whether a research service is suitable for you, as SEBI requires before recommending it You
Signed agreement and Most Important Terms and Conditions, with the eSign audit trail Evidence that a valid agreement exists, which SEBI requires me to hold You, through the eSign provider
Payment records: amount, date, reference, method, and the last four digits of a card where the gateway returns them To confirm payment, issue receipts, calculate refunds, and meet accounting and audit obligations The payment gateway
Telegram username or user id, where you take delivery through Telegram To add you to the research channel for the plan you paid for, and to remove you when it ends You, through Telegram
Service records: which plan, when it started and ended, complaints, and correspondence To run the service and to maintain the registers SEBI requires a Research Analyst to keep Generated by the service
Technical logs: IP address, browser type, timestamps of sign-in and key actions Security, fraud prevention, and the audit trail that shows who did what and when Automatically, when you use the site

What is never collected here. I do not ask for and do not store your Aadhaar number, your bank account number, your card number, your card expiry, your CVV, your UPI PIN, or any password to another service. Card and UPI details are entered on the payment gateway's own screen and never reach my server. Where Aadhaar is used at all, it is used inside the KRA's own verified process, and only a masked reference comes back.

3. The legal basis for holding it

4. Who your data is shared with

These are the only categories of recipient, and each receives only what it needs to do its job.

RecipientWhat they receiveWhy
KFIN Technologies (KFIN KRA), a SEBI-registered KYC Registration Agency PAN, date of birth, name, mobile, email, and the KYC record To check and record your KYC, which SEBI requires before a client is taken on
The eSign provider (Leegality, and the licensed eSign service behind it) Name, email, mobile, and the agreement document To have the agreement signed electronically with a legally valid signature
The payment gateway (Razorpay) Name, email, mobile, amount, and the order reference To take payment and to process refunds. Your card, netbanking or UPI credentials are handled entirely by them and are never seen by me
Telegram, where you choose delivery through Telegram Your Telegram username or user id only To give and withdraw access to the research channel for your plan
Email delivery provider Your email address and the message being sent To deliver agreements, receipts and service email
SEBI, BSE, a designated Research Analyst Administration and Supervisory Body, an auditor, or a court or law-enforcement authority Whatever the applicable regulation, inspection, audit or lawful order requires Legal and regulatory obligation. I cannot refuse a lawful request, and I do not treat this as optional

I do not sell personal data. I do not share it with advertisers or data brokers. I do not use it to train any machine-learning model, mine or anyone else's.

5. Where data is held

Data is stored on servers located in India, and the vendors named above operate in India under Indian regulation. Where a technical service processes data outside India, it is limited to what that service needs and to countries not restricted by the Government of India for such transfers.

6. How long it is kept

This is why a request to delete everything cannot always be granted in full while the retention period runs. I will say so plainly and delete what is not caught by it, rather than quietly ignoring the request.

7. Your rights

You may ask me to:

Write to dwipanjit.researchanalyst@gmail.com. I acknowledge within 3 working days and respond within 7 business working days, which is the same timetable SEBI sets for resolving a grievance. There is no charge.

8. Cookies and analytics

The site uses cookies that are necessary for it to work: keeping you signed in, and protecting forms against cross-site request forgery. These cannot be switched off without breaking sign-in. If analytics or any non-essential cookie is introduced later, this section will say so and consent will be asked for before it is set, not after.

The visit count shown in the footer. This page counts visits so a figure can be published, and it is built to hold nothing about you. No cookie is set for it. Your browser keeps a single flag in sessionStorage so that one visit is counted once rather than once per page you open; that flag is erased when you close the tab and is never sent anywhere. What reaches the server is a request carrying no identifier, and what the server keeps is one row per day holding a date and a number — no IP address, no hash of one, no device or browser details, nothing that could be traced to a person. There is therefore nothing in that record to ask consent for, to disclose to you on request, or to lose in a breach.

One qualification, stated because it is true rather than because it has to be: the request is rate-limited by IP address, as every public endpoint on this site is, so that the published figure cannot be inflated by repeatedly reloading the page. That address is held in memory for the length of the limit window and is not written to disk or to any record.

Because the count cannot tell a returning reader from a new one, the footer says visits. It is not a count of people, of investors, or of clients, and it is not presented as one.

9. Security

The site is served over HTTPS. Vendor keys and other secrets are encrypted at rest and are never displayed back once saved, so they can be replaced but not read out. Access to the administration console is restricted and every action is written to an audit trail with who did it and when. Payment credentials never touch my server, because they are entered on the gateway's own screen.

No system is perfect. If a breach occurs that is likely to affect you, I will inform you and the Data Protection Board of India as the law requires, and tell you what happened rather than minimising it.

10. Children

Research services are not offered to anyone under 18. If a minor's data reaches me, it is deleted once identified.

11. Changes to this policy

If this policy changes, the revised version is published here with a new date at the top. Where a change materially affects how your data is used, existing clients are told by email rather than left to notice it.

12. Contact and grievances

Dwipanjit Handique
SEBI Registered Research Analyst · Registration No. INH000028936
Email: dwipanjit.researchanalyst@gmail.com
Phone: +91 88220 68674
C/o House No. 5, 2nd Floor, Laxminath Bezbaruah Path, Hatigaon, Guwahati – 781038, Assam

If you are not satisfied with how a privacy matter has been handled, you may escalate to the Data Protection Board of India. For matters concerning research services, you may also use SEBI's SCORES portal or the SMART ODR platform. Details of the grievance process are on the home page.